When Are Legitimate Apps Actually Malicious?
Uncovering malicious app registration using behavioral analysis.
Historically, attackers used only a short list of sketchy apps as persistence mechanisms during a compromise. While some people had real reasons to use them, security teams often adapted by simply blocking them outright.
Over the past several months, we've seen attackers adapt by leveraging popular apps that most people use legitimately.
If you understand both the behavior (the app registration and how the app is used) and the intent behind the behavior, these malicious app registrations can be valuable signals for detecting a compromise.
Combining an Unusual Login with Suspicious Activity
Below is a login for a compromise that we uncovered during a retrospective Petra Scan. The compromise occurred before Petra was onboarded.
In this case, the user, an Austin native, logged in from Phoenix for the first time ever. They also logged in from a brand new app, "officehome." Taken by itself, this is not particularly unusual. The travel was not impossible, and traveling users are more likely to use new apps.

However, just after they logged in, they immediately signed the user up for Attio, a common CRM tool which can sync with email inboxes, and then quickly deleted both a "Your email has finished syncing with Attio" and a "Welcome to Attio!" email from the inbox.

Analyzing Behavior around the Registration
On their own, none of these actions indicate a compromise. A traveling user simply logged in, signed up for a common SaaS tool, and then deleted a welcome email and an onboarding email. Maybe this user just likes to keep a tidy inbox!
However, when you combine the unusual login, the app registration, and the email deletions, what may have seemed like a string of independently benign actions reveals a clearly compromised account.
Why Catching Malicious Apps Matters
Attackers commonly use these benign tools as the very first step of their attack after login. They know that this is their least likely to be detected tactic, so they lead with it. Then, they move on to more obviously malicious actions, like sending fraudulent emails.
In the case above, the attacker sent out 600+ fraudulent emails a few hours after they installed Attio.
If the attack had been detected when Attio was installed, the attack would've stopped there, avoiding significant reputational harm and potential financial harm.

Even if the app wasn't used to detect the compromise, it's still important to flag as part of the attack. Some tools (like Attio) sync with email mailboxes even after the compromise is locked out. If your detection flagged on a malicious inbox rule or a fraudulent email send, you might not have uncovered that Attio was another layer of the attack and failed to remediate it. The app could remain installed, stealing emails long after the password is reset and the session is revoked.
Takeaways:
- Attackers use legitimate apps maliciously.
- The malicious intent can be detected quickly through behavioral analysis.
See what's in your last six months of logs.
Get insurance-grade forensics on the last 6 months of your M365 logs. Setup takes 5 minutes with results in 48 hours.


